๐ฉ๐ช
IVski.com
2026-09-14 18:44:51
(2 days ago)
IVski WAF | Sensitive file probe - looking for exposed .git/config
Hacking
Brute-Force
Web App Attack
๐น๐ท
ayayntr
2026-09-14 13:36:40
(2 days ago)
[Mon Sep 14 16:36:38.238437 2026] [proxy_fcgi:error] [pid 368623:tid 368668] [client 34.65.35.91:424 ...
show more
[Mon Sep 14 16:36:38.238437 2026] [proxy_fcgi:error] [pid 368623:tid 368668] [client 34.65.35.91:42438] AH01071: Got error 'Primary script unknown'
[Mon Sep 14 16:36:38.321888 2026] [proxy_fcgi:error] [pid 368623:tid 368661] [client 34.65.35.91:42438] AH01071: Got error 'Primary script unknown'
[Mon Sep 14 16:36:38.430581 2026] [proxy_fcgi:error] [pid 368623:tid 368670] [client 34.65.35.91:42438] AH01071: Got error 'Primary script unknown'
[Mon Sep 14 16:36:38.524361 2026] [proxy_fcgi:error] [pid 368623:tid 368671] [client 34.65.35.91:42438] AH01071: Got error 'Primary script unknown'
[Mon Sep 14 16:36:38.581990 2026] [proxy_fcgi:error] [pid 368623:tid 368652] [client 34.65.35.91:42438] AH01071: Got error 'Primary script unknown'
...
show less
Brute-Force
SSH
๐ต๐ฑ
Budyn
2026-09-14 13:35:16
(2 days ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: ssh.astropot.online | URI: /.git/config | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-14 07:28:10
(2 days ago)
20 attempts against mh-misbehave-ban on ozone
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
2000cn.com.au
2026-09-14 06:55:17
(2 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ฟ๐ฆ
conure.sh
2026-09-14 06:28:47
(2 days ago)
csagent: score 19.9: secrets grab x2; 1 domain(s) in 2s
Web App Attack
๐ท๐ด
clauss
2026-09-14 05:36:45
(3 days ago)
34.65.35.91 - - [14/Sep/2026:08:36:45 +0300] "GET /phpinfo.php HTTP/2.0" 301 281 "-" "Mozilla/5.0 (M ...
show more
34.65.35.91 - - [14/Sep/2026:08:36:45 +0300] "GET /phpinfo.php HTTP/2.0" 301 281 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.65.35.91 - - [14/Sep/2026:08:36:45 +0300] "GET /info.php HTTP/2.0" 301 281 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Web App Attack
Anonymous
2026-09-14 05:32:57
(3 days ago)
(mod_security) mod_security triggered on hostname [redacted] 34.65.35.91 (CH/Switzerland/91.35.65.34 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.65.35.91 (CH/Switzerland/91.35.65.34.bc.googleusercontent.com)
show less
SQL Injection
๐ฎ๐น
madaello
2026-09-14 05:31:31
(3 days ago)
34.65.35.91 - - [14/Sep/2026:07:31:30 +0200] "GET /.git/config HTTP/1.1" 404 570 "-" "Mozilla/5.0 (M ...
show more
34.65.35.91 - - [14/Sep/2026:07:31:30 +0200] "GET /.git/config HTTP/1.1" 404 570 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.65.35.91 - - [14/Sep/2026:07:31:30 +0200] "GET /.git/config HTTP/1.1" 404 556 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.65.35.91 - - [14/Sep/2026:07:31:30 +0200] "GET /.env HTTP/1.1" 404 570 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.65.35.91 - - [14/Sep/2026:07:31:30 +0200] "GET /.env.local HTTP/1.1" 404 570 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.65.35.91 - - [14/Sep/2026:07:31:30 +0200] "GET /.env HTTP/1.1" 404 556 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Port Scan
๐จ๐ญ
๐จ๐ญ Hosting
2026-09-14 05:10:35
(3 days ago)
Automated WAF report: 200-300 blocked requests from this IP detected by our WAF.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-14 04:51:40
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.65.35.91 (91.35.65.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.35.91 (91.35.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 00:51:35.703269 2026] [security2:error] [pid 2984:tid 2984] [client 34.65.35.91:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sportsbookcommission.com"] [uri "/.git/config"] [unique_id "aqd9Vwt5h_5J2YT0ucP3SgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Tha_14
2026-09-14 03:12:25
(3 days ago)
Multiple erroneous requests
Web App Attack
๐ณ๐ฑ
ConsulHosting
2026-09-14 02:42:24
(3 days ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
๐ฌ๐ง
consul.to
2026-09-14 01:50:09
(3 days ago)
Web attack/malicious scanning detected
Web App Attack
๐ฎ๐น
VHosting
2026-09-14 01:50:03
(3 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack